Clear licensing, documentation, tests, and a matching repository provide a solid foundation. The small maintainer and contributor base, limited recent activity, and workflow hygiene make long-term upkeep less certain.
57%
Total Score
50
100
89
67
All four workflows were analyzed, but all nine action references are unpinned. A high-confidence bot-conditions finding affects the Dependabot auto-merge workflow, and two workflows grant top-level write access, creating meaningful workflow-maintenance risk.
A post-autoload-dump Composer script is present. This is common package setup behavior, but it adds install-time execution that consumers should understand.
Only one account has registry publish access. The linked project is user-owned rather than organization-backed, so this represents a genuinely thin publishing and maintenance base.
The registry namespace and repository belong to the same individual account. This supports ownership consistency, but it does not provide organization-level backing.
The package has four releases over about 2.5 years, with one release in the last year and intervals of roughly seven months. This indicates slow maintenance rather than abandonment by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/contracts Version ^11.0||^12.0||^13.0 | — | — |
spatie/laravel-package-tools Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.